CERT-In Vulnerability Note
CIVN-2022-0488
Authentication Bypass Vulnerability in NetApp OnCommand Insight
Original Issue Date:December 28, 2022
Severity Rating: HIGH
Software Affected
- NetApp OnCommand Insight versions 7.3.1 through 7.3.14
Overview
A vulnerability has been reported in NetApp OnCommand Insight products which could allow an unauthenticated attacker to bypass security restriction on the targeted system.
Description
This vulnerability exists due to an error in the Data Warehouse component. An attacker could exploit this vulnerability by sending a specially crafted request.
Successful exploitation of this vulnerability could allow an unauthenticated attacker to bypass authentication process, view limited configuration data, view operations or perform privileged operations on the administrative interface on the targeted system.
Solution
Update to the latest version:
https://security.netapp.com/advisory/ntap-20221220-0001/
Vendor Information
NetApp
https://security.netapp.com/advisory/ntap-20221220-0001/
References
NetApp
https://security.netapp.com/advisory/ntap-20221220-0001/
CVE Name
CVE-2022-38733
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|